Turn this role into an interview — a resume and cover letter built around what this employer wants.
Ferguson is seeking a Senior Manager in Security Engineering to provide vision and operational accountability for enterprise security capabilities across applications, infrastructure, cloud platforms, endpoints, and identity-enabled services. You will lead multiple teams, drive risk-driven priorities, and partner with cross-functional technology groups to harden baselines and validate defenses.
The role requires deep technical judgment, strong leadership, and the ability to translate complex
Ferguson, Information Security Reports To: Director, Information Security
The Senior Manager, Security Engineering provides vision, leadership, and operational accountability for Ferguson’s enterprise security engineering capabilities. This role leads the teams and services responsible for identifying, reducing, and reporting technology risk across applications, infrastructure, cloud platforms, endpoints, identity-integrated services, email, edge protections, and emerging AI-enabled attack surfaces. The leader is accountable for ensuring Ferguson has the people, processes, tooling, and partnerships required to continuously assess risk, harden technology baselines, validate defenses, support secure delivery, and drive remediation in partnership with Technology, Security, business, and third-party participants. This position requires deep technical judgment, collaborative leadership, and operational rigor. It also requires the ability to translate complex security risks into actionable priorities. These priorities help Ferguson complete its business plans securely.
Location: This role is approved to be either Remote within the United States or Hybrid for associates in Newport News, VA, in accordance with company policy.
Build, lead, and develop a high-performing Security Engineering team through recruiting, hiring, coaching, mentorship, performance management, and career development. Define and maintain the operating model, service ownership, roadmap, and measurable objectives related to Security Engineering capabilities across vulnerability management, DevSecOps, penetration testing, edge security, email security, endpoint security, cloud and configuration posture, and related engineering services. Represent Security Engineering performance, risks, resource needs, and strategic opportunities with Information Security leadership and multi-functional Technology leadership forums. Partner with Security Architecture, Security Operations, GRC, Identity, Infrastructure, Application Development, Cloud, and business technology teams to align engineering priorities to enterprise risk reduction and business enablement. Continuously assess team skills, capacity, vendor support, and tooling maturity against current and emerging threats, including AI-enabled attack techniques and post-quantum readiness considerations. Drive a culture of secure-by-default engineering, shared accountability, transparency, and practical risk-based decision making across Ferguson technology teams. Establish clear metrics, performance indicators, reporting routines, and executive-ready narratives that communicate risk posture, control effectiveness, remediation progress, service value, and investment needs.
Own and mature Security Engineering service areas including vulnerability management, DevSecOps, penetration testing and adversarial validation, edge security, email security, endpoint detection and response, cloud security posture, configuration risk, application security testing, and security tooling integrations. Lead Ferguson’s risk-based vulnerability management capability, ensuring asset visibility, authenticated scanning, application and infrastructure assessment, risk contextualization, remediation tracking, exception management, and leadership reporting are operating effectively. Advance secure software delivery by integrating security testing and guidance into development workflows, including static analysis, software composition analysis, container security, secrets protection, code signing, secure repository practices, and developer-facing remediation support. Run penetration testing, AI-enabled security testing, purple team support, and continuous adversarial validation activities for critical applications, APIs, external assets, cloud services, identity entry points, and business-critical technology platforms. Ensure public-facing applications and digital channels are protected through effective use of edge security capabilities, including WAF, bot management, CDN security, origin protection, API protections, and secure traffic patterns. Provide engineering ownership and oversight for email and endpoint security capabilities, including migration planning, policy tuning, telemetry quality, detection support, deployment health, and operational readiness. Drive enterprise configuration and posture management across cloud, infrastructure, endpoints, applications, and identity-adjacent services to identify deviations from hardened baselines and support timely remediation. Partner with Identity, PAM, SSO, certificate, and non-human identity teams where security engineering capabilities depend on identity controls, privileged access, machine identity, key management, or cryptographic services. Support pivotal initiatives such as AI resilience, post-quantum readiness, enterprise cryptographic visibility, secrets removal, cloud posture modernization, and security tooling rationalization. Ensure Security Engineering platforms and service offerings are reliable, monitored, documented, supportable, and aligned with published policies, standards, organizational change expectations, and regulatory or audit obligations. Establish and maintain runbooks, customer concern paths, operational handoffs, service ownership documentation, vendor engagement models, and cross-training practices to prevent coverage gaps. Prioritize engineering work based on business risk, exploitability, asset criticality, exposure, compliance requirements, operational impact, and available remediation capacity. Partner with Technology teams to close visibility and deployment gaps in required security tooling so Ferguson can assess and protect operational assets consistently. Contribute technical requirements to security technology selection, proof-of-value efforts, vendor evaluations, architecture reviews, and implementation planning. Actively monitor new and emerging technologies, threats, attack patterns, regulatory expectations, and industry practices to assess their applicability to Ferguson’s security engineering program. Perform other duties or functions as requested by management. Drive and report on Service restoration activities as required. Support enterprise business and sales objectives through the effective and efficient performance of job responsibilities.
Pay Range: - Actual pay rate may vary depending upon location. The estimated pay range for this position is below. The specific rate will depend on a candidate’s qualifications and prior experience. - $9,458.97 - $16,551.03 - Estimated Ranges displayed are Monthly for Salaried roles OR Hourly for all other roles. - This role is Bonus or Incentive Plan eligible. - Ferguson complies with all wage regulations. The starting wage may be higher in certain locations based on local or state wage requirements.
The Company is an equal opportunity employer as well as a government contractor that shall abide by the requirements of 41 CFR 60-300.5(a), which prohibits discrimination against qualified protected Veterans and the requirements of 41 CFR 60-741.5(A), which prohibits discrimination against qualified individuals on the basis of disability. Ferguson Enterprises, LLC. is an equal employment employer F/M/Disability/Vet/Sexual Orientation/Gender Identity. Equal Employment Opportunity and Reasonable Accommodation Information Ferguson is a project success company providing expertise, solutions and products from infrastructure, plumbing and appliances to HVAC, fire, fabrication and more. As a leading value-added distributor of residential and commercial plumbing supplies and pipe, valves and fittings in the U.S., we exist to make our customers’ complex projects simple, successful and sustainable. The professionals we serve help transform the world we live in, and we are their trusted partners with the scale to provide peace of mind. Founded in 1953, Ferguson is part of Ferguson plc, which is listed on the New York Stock Exchange (NYSE: FERG) and London Stock Exchange (LSE: FERG). With approximately 36,000 associates across 1,700 places, Ferguson plc serves customers in all 50 states, Canada, Puerto Rico, Mexico and the Caribbean.
We value our well-being just as much as our hard work. We are committed to a holistic approach towards benefits plans and programs that support the mental, physical and financial well-being of our associates. Our competitive offering not only includes benefits like health, dental, vision, paid time off, life insurance and a 401(k) with a company match, but our associates also enjoy additional meaningful and inclusive enhancements that are adaptable to their diverse situations and needs, including mental health coverage, gender affirming and family building benefits, paid parental leave, associate discounts, community involvement opportunities and more!